Articles tagged "Malware"

Found 828 articles

North Korean hackers are behind a campaign known as PolinRider, which has compromised over 100 legitimate open source packages and repositories. The attackers are using these compromised resources to deliver a backdoor and an information-stealing malware to unsuspecting developers. This incident is particularly concerning as it targets the open source community, which often relies on shared code and collaboration. Developers who unknowingly use these tainted packages may expose their systems and sensitive information to further exploitation. The implications are significant, as it raises questions about the security of open source software and the risks developers face when integrating third-party code into their projects.

Read Original

This week, several cybersecurity issues emerged, highlighting vulnerabilities in everyday technology. Home devices are being exploited as routing tools for proxy botnets, allowing attackers to route malicious traffic through unsuspecting networks. Additionally, researchers discovered that clean code can inadvertently introduce vulnerabilities through flawed dependencies. AI systems are also being misled by incorrect instructions, raising concerns about their reliability. These incidents emphasize a common theme: many systems and processes that people trust are not as secure as they should be, potentially putting users at risk. As the lines blur between convenience and security, users and developers alike must be more vigilant about the technologies they rely on.

Read Original
Critical
ClickFix Scams Abuse Google, Cloudflare Checks to Deliver 7 Malware Families

Hackread – Cybersecurity News, Data Breaches, AI and More

Actively Exploited

Malwarebytes has reported that attackers are using fake Google and Cloudflare verification pages as part of a scheme to distribute multiple families of malware, including StealC and NetSupport. This operation is linked to a shared infrastructure known as ClickFix. The fraudulent pages trick users into believing they are legitimate, making it easier for the malware to be delivered. This affects anyone who may inadvertently interact with these deceptive sites, potentially leading to data theft and system compromise. The incident emphasizes the need for users to be cautious about online verifications and the sites they engage with, as the risks of malware infections continue to rise.

Read Original

A group of hackers, believed to be linked to China, has launched a campaign targeting Indian taxpayers and finance professionals using a fake tax filing tool. This operation, dubbed Operation DragonReturn by Seqrite Labs, involves sending emails that appear to be from the Income Tax Department of India. The goal is to deliver a remote access trojan (DcRAT) that can steal sensitive information from infected systems. This attack not only threatens individual taxpayers but also poses risks to corporate finance teams who handle sensitive financial data. As cyber threats continue to evolve, awareness and vigilance are crucial for those in the affected sectors.

Read Original

A new cyber threat group called Armored Likho has been linked to attacks against government agencies and the electric power sector in Russia, Brazil, and Kazakhstan. Researchers from Kaspersky report that this group combines financially motivated schemes targeting individuals with cyber espionage aimed at organizations. The BusySnake Stealer malware is being used in these operations, which raises concerns about the potential for sensitive data breaches. The targeting of critical infrastructure like power sectors is particularly alarming, as it can have severe implications for national security and public safety. Organizations in affected regions should bolster their cybersecurity measures to defend against these types of attacks.

Read Original

Researchers from Jamf Threat Labs have identified a new malware targeting macOS users, named PamStealer. This information stealer masquerades as a legitimate application called Maccy, which is a popular open-source clipboard manager. By distributing a compiled AppleScript file that looks legitimate, PamStealer tricks users into downloading it. Once installed, it seeks to extract sensitive information, including Mac login passwords. This incident is concerning for Mac users, as it highlights the ongoing risks posed by malware that exploits trusted applications to gain access to personal data.

Read Original

A new malware called Umbrij, linked to the cyber group ToddyCat, is targeting corporate Gmail accounts by exploiting the Google API. According to Kaspersky's recent report, the malware allows attackers to gain stealthy access to email communications, raising significant concerns for businesses that rely on Gmail for their operations. This tactic of compromising access through APIs highlights potential vulnerabilities in how companies manage their email systems. As email remains a primary communication tool for organizations, the implications of such breaches could be severe, resulting in sensitive information leaks and potential financial losses. Companies using Gmail should enhance their security measures to safeguard against this type of attack.

Read Original

Opera has introduced a new feature called Paste Protect to enhance security against clipboard-based attacks, specifically targeting ClickFix attacks. These types of attacks have become increasingly common, responsible for over half of malware delivery incidents in 2025. Paste Protect is automatically enabled in Opera's desktop browsers, meaning users don’t have to take any additional steps to benefit from this protection. The feature warns users of potential threats when they attempt to paste content that may have been compromised. This move is significant as clipboard hijacking can lead to serious security issues, affecting user data integrity and privacy.

Read Original

A new malware named ChocoPoC is targeting cybersecurity researchers through malicious proof-of-concept (PoC) exploits available on GitHub. This Python-based remote access trojan (RAT) allows attackers to execute commands and steal sensitive data from infected systems. The campaign appears to specifically aim at individuals in the cybersecurity field, raising concerns about the security of research and development environments. Researchers need to be vigilant when downloading and executing code from public repositories, as this can lead to serious data breaches. The incident underscores the ongoing risks associated with open-source software and the need for enhanced security measures in research practices.

Read Original
Actively Exploited

Researchers have identified ClickFix as a dominant method for delivering malware, showcasing how social engineering tactics have become standard practice in cyberattacks. This technique exploits human psychology, tricking users into clicking on malicious links or attachments. As a result, organizations and individuals are increasingly susceptible to these attacks, which can lead to data breaches and financial losses. The shift towards ClickFix as a primary delivery method emphasizes the need for heightened awareness and training for users to recognize suspicious activities. Companies should bolster their cybersecurity strategies to defend against these evolving threats.

Read Original
Critical
Fake Interpol Investigation Emails Push Ransomware at Small Businesses Globally

Hackread – Cybersecurity News, Data Breaches, AI and More

Actively Exploited

Small businesses are facing a new threat from fake emails that appear to come from Interpol. These emails contain links to Proton Drive, which, when clicked, deliver ransomware to victims' systems. The ransomware encrypts files, effectively locking businesses out of their data. Additionally, the malware directs users to Tox chat, which may facilitate further malicious activity. This incident is particularly concerning as it targets smaller companies that may lack robust cybersecurity measures, making them more vulnerable to such attacks. Businesses need to be vigilant about phishing attempts and ensure they have adequate protections in place.

Read Original
Actively Exploited

A new Brazilian banking trojan named Ousaban is now targeting users in Spain and Portugal through phishing attacks, according to FortiGuard researchers. This malware is designed to steal sensitive banking information, posing a significant risk to individuals and financial institutions in these countries. Phishing typically involves deceptive emails or messages that trick users into revealing personal data or downloading malicious software. As Ousaban spreads, it raises concerns about the vulnerability of online banking systems and highlights the need for robust security measures among users. Both individuals and businesses in Spain and Portugal should remain vigilant against suspicious communications and take steps to protect their financial information.

Read Original

Kaspersky researchers have identified a large-scale campaign that uses compromised ScreenConnect software to deliver AsyncRAT, a type of remote access Trojan. Attackers are exploiting vulnerabilities in the legitimate ScreenConnect application to drop the malicious payload onto targeted systems. This incident raises concerns for users and organizations that rely on ScreenConnect for remote access, as they may unknowingly become victims of this malware. The report details the infection chain and the command and control (C2) infrastructure used in the attack, emphasizing the need for vigilance in software downloads and updates. Users should ensure they are downloading software from official sources and remain cautious of unsolicited software offers.

Read Original
Actively Exploited

A new security issue, dubbed 'agentjacking', has emerged, revealing how attackers can manipulate AI coding agents. This tactic exploits the agents' inability to distinguish between content and instructions, allowing malicious actors to hijack their operations. The implications are significant, as many organizations rely on AI for coding and development tasks, making them vulnerable to these kinds of attacks. As AI technology continues to evolve, this incident raises concerns about the security of automated systems and the potential for widespread exploitation. Companies that utilize these AI agents need to be vigilant and implement safeguards to prevent such hijacking attempts.

Read Original

A new malware called RustDuck is actively hijacking various devices, including home routers, IP cameras, Android boxes, and poorly secured servers. The malware operates in two stages and connects these compromised devices into a botnet designed to launch Distributed Denial of Service (DDoS) attacks, effectively taking websites and online services offline. Researchers from QiAnXin's XLab have been monitoring RustDuck since February 2026 and note that its rapid evolution is particularly concerning. This highlights the vulnerability of consumer devices and poorly secured servers, which can be easily exploited by attackers. Users and organizations need to ensure their devices are secured to prevent becoming part of such a botnet.

Read Original
PreviousPage 18 of 56Next